Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Ivanti Endpoint Manager Mobile Vulnerabilities Allow Attackers to Decrypt Other Users’ Passwords

Ivanti has identified and resolved three high-severity vulnerabilities in its Endpoint Manager (EPM) software.

Ivanti has identified and resolved three high-severity vulnerabilities in its Endpoint Manager (EPM) software.

If exploited, these flaws could enable attackers to decrypt other users’ passwords or gain access to sensitive database information, posing significant risks to organizations that rely on this endpoint management solution.

Ivanti Endpoint Manager Mobile Vulnerabilities

Ivanti’s recent security update targets three specific vulnerabilities, each with a high severity rating based on the Common Vulnerability Scoring System (CVSS).

Two of these flaws, identified as CVE-2025-6995 and CVE-2025-6996, stem from improper use of encryption in the EPM agent. Both carry a CVSS score of 8.4 (High) and could enable a local authenticated attacker to decrypt passwords of other users.

The third vulnerability, CVE-2025-7037, involves an SQL injection flaw with a CVSS score of 7.2 (High), allowing a remote authenticated attacker with admin privileges to read arbitrary data from the database.

Here’s a detailed breakdown of the vulnerabilities:

Ivanti has identified and resolved three high-severity vulnerabilities in its Endpoint Manager (EPM) software.
Katherine Doyle · Thehackingpost

CVE NumberDescriptionCVSS ScoreCVSS VectorCWECVE-2025-6995Improper encryption in EPM agent allows local authenticated attacker to decrypt passwords.8.4 (High)CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:NCWE-257CVE-2025-6996Improper encryption in EPM agent allows local authenticated attacker to decrypt passwords.8.4 (High)CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:NCWE-257CVE-2025-7037SQL injection in EPM allows remote admin attacker to read database data.7.2 (High)CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HCWE-89 These vulnerabilities affect Ivanti Endpoint Manager versions prior to 2024 SU3 and 2022 SU8 Security Update 1. The encryption flaws specifically target the agent component, making local access a potential gateway for attackers to compromise user credentials.

Ivanti has identified the following versions of Endpoint Manager as vulnerable, with corresponding resolved versions now available:

Product NameAffected Version(s)Resolved Version(s)Patch AvailabilityIvanti Endpoint Manager2022 SU8 and prior2022 SU8 Security Update 1Download Available in ILSIvanti Endpoint Manager2024 SU2 and prior2024 SU3Download Available in ILS Organizations using affected versions are urged to update immediately to the resolved versions 2024 SU3 or 2022 SU8 Security Update 1—accessible through Ivanti’s licensing portal (login required). These updates fully mitigate the identified risks.

Ivanti has emphasized that there is no evidence of active exploitation of these vulnerabilities prior to their disclosure. The issues were reported through the company’s responsible disclosure program, ensuring timely patches before any known attacks.

However, with no public indicators of compromise currently available, organizations must remain vigilant and prioritize updates to prevent potential breaches.

Advertisement

The ability for attackers to decrypt passwords or access database information underscores the importance of robust endpoint security. While local access is required for two of the vulnerabilities, the SQL injection flaw opens a remote attack vector for those with admin privileges, broadening the potential threat surface.

IT administrators should audit their systems for affected versions of Ivanti Endpoint Manager and apply the necessary updates without delay. Additionally, monitoring for unusual activity could serve as a precaution, even though no exploitation has been reported.

This incident highlights the ongoing challenges in securing endpoint management tools, which are critical for organizational IT infrastructure.

Investigate live malware behavior, trace every step of an attack, and make faster, smarter security decisions -> Try ANY.RUN now

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories